Set Password Maximum Consecutive Repeating Characters
Limits how many times the same character may repeat in a row in a password by setting maxrepeat = 3.
Checked against the content of a persistent configuration file, the source of truth that survives reboots.
A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.
Why this rule matters
A complex password increases the time and resources needed to compromise it. The maxrepeat parameter rejects passwords with long runs of the same character (e.g. aaaa, 1111). Excessive repetition shrinks the effective entropy and creates predictable patterns that password-guessing and rule-based attacks exploit. Capping repeats at 3 preserves randomness and resists such attacks.
What Pavois checks
Pavois reads the effective maxrepeat value across /etc/security/pwquality.conf and all drop-ins under /etc/security/pwquality.conf.d/, keeping the last definition that wins at runtime. A file-based scanner reading only the main config would miss a value set in a drop-in. The control passes only when the resolved value is <= 3 (and non-zero, since 0 disables the check).
describe command('v=$(grep -rh \'^[[:space:]]*maxrepeat[[:space:]]*=\' /etc/security/pwquality.conf /etc/security/pwquality.conf.d/ 2>/dev/null | tail -1 | grep -oE \'[-]?[0-9]+\'); { [ -n "$v" ] && [ "$v" -le 3 ] && echo ok; } || echo ko') do
its('stdout.strip') { should eq 'ok' }
endHow to verify it is applied
Run grep -rh '^[[:space:]]*maxrepeat' /etc/security/pwquality.conf /etc/security/pwquality.conf.d/ | tail -1. The effective line must read maxrepeat = 3 (or any value 1..3).
Inspect & investigate
Password changes rejected for too many repeated characters are logged via PAM in /var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL family) with pam_pwquality messages like "Too many same consecutive characters". Inspect the live setting with grep -r maxrepeat /etc/security/pwquality.conf.d/.
Remediation
pavois harden apply writes maxrepeat = 3 to the drop-in /etc/security/pwquality.conf.d/99-Pavois.conf via the idempotent keyval resource. The 99- prefix ensures it overrides any earlier value. No service restart is needed; it applies at the next password change.
Pavois applies this with its own harden engine, the plan below, not a shell script:
| file | /etc/security/pwquality.conf.d/99-pavois.conf |
|---|---|
| key | maxrepeat |
| resource | keyval |
| value | 3 |
pavois harden plan localwhere the target is local, a user@host SSH alias, or a container , Docs
Impact & precautions
Existing passwords stay valid; only new passwords are constrained. Users picking passwords with four or more identical characters in a row will be rejected. Lockout risk is minimal; the main precaution is ensuring automated password generators do not by chance emit long repeat runs (rare). Setting maxrepeat = 0 would silently disable the check, so verify the value is 1..3.
Standards mapping
| Standard | Reference | Type | Version | Confidence |
|---|---|---|---|---|
| CIS | 5.3.3.2.4 | direct | per OS, see the benchmark table | high |
| NIST | CM-6(a), IA-5(4), IA-5(c) | supporting | 800-53 Rev 5 · 800-171 Rev 2 (pinned) | medium |
Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.